research

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • Dynamic Initialization Pattern: The skill instructions in SKILL.md specify running a 'preflight script' from the user-context skill when local shell access is available. This is a functional initialization step that allows the agent to prepare the environment before starting research tasks.
  • Internal Data Access: To fulfill its research purpose, the skill is configured to access internal repositories and communication tools like Slack, Jira, and Google Drive. This involves processing potentially sensitive internal information to identify product workflows and friction points, which is a core capability of the tool.
  • Indirect Prompt Injection Surface: The workflow involves searching and ingesting data from public platforms like Reddit and GitHub. This represents a potential surface for indirect prompt injection where instructions embedded in external content could be encountered by the agent.
  • Ingestion points: Public sources (Reddit, X, GitHub issues, YouTube) and internal sources (Slack, Jira, Google Drive) as listed in SKILL.md.
  • Boundary markers: None explicitly defined to delimit external content from system instructions.
  • Capability inventory: Internal connectors, web search capabilities, and potential shell access via the referenced preflight script.
  • Sanitization: No specific content filtering or validation rules are defined for the ingested research data.
  • Operational Guidelines: The skill contains 'Critical Overrides' that direct the agent to safety and routing references (index/SKILL.md and critical-overrides.md), ensuring it operates within the platform's defined boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 09:18 AM
Security Audit — agent-trust-hub — research